admin.apps.permissions.set method | Slack Developer Docs
https://docs.slack.dev/reference/methods/admin.apps.permissions.set/ • 98 KB fetched Open original page
admin.apps.permissions.set method | Slack Developer Docs
reference
Skip to main content
Guides Reference Samples Tools
Changelog Dev Program
MANAGE APPS
* Reference
* App manifest
* Block Kit
* Events
* Interaction payloads
* Methods
* Overview
* admin
* admin.analytics.getFile
* admin.analytics.messages.activity
* admin.analytics.messages.metadata
* admin.apps.activities.list
* admin.apps.approve
* admin.apps.approved.list
* admin.apps.clearResolution
* admin.apps.config.lookup
* admin.apps.config.set
* admin.apps.mcp.servers.list
* admin.apps.mcp.servers.permissions.list
* admin.apps.mcp.servers.permissions.set
* admin.apps.permissions.add
* admin.apps.permissions.list
* admin.apps.permissions.remove
* admin.apps.permissions.set
* admin.apps.requests.cancel
* admin.apps.requests.list
* admin.apps.restrict
* admin.apps.restricted.list
* admin.apps.uninstall
* admin.audit.anomaly.allow.getItem
* admin.audit.anomaly.allow.updateItem
* admin.auth.policy.assignEntities
* admin.auth.policy.getEntities
* admin.auth.policy.removeEntities
* admin.barriers.create
* admin.barriers.delete
* admin.barriers.list
* admin.barriers.update
* admin.conversations.archive
* admin.conversations.bulkArchive
* admin.conversations.bulkDelete
* admin.conversations.bulkMove
* admin.conversations.bulkSetExcludeFromSlackAi
* admin.conversations.bulkSetProperties
* admin.conversations.convertToPrivate
* admin.conversations.convertToPublic
* admin.conversations.create
* admin.conversations.createForObjects
* admin.conversations.delete
* admin.conversations.disconnectShared
* admin.conversations.ekm.listOriginalConnectedChannelInfo
* admin.conversations.getConversationPrefs
* admin.conversations.getCustomRetention
* admin.conversations.getTeams
* admin.conversations.invite
* admin.conversations.linkObjects
* admin.conversations.lookup
* admin.conversations.removeCustomRetention
* admin.conversations.rename
* admin.conversations.restrictAccess.addGroup
* admin.conversations.restrictAccess.listGroups
* admin.conversations.restrictAccess.removeGroup
* admin.conversations.search
* admin.conversations.setConversationPrefs
* admin.conversations.setCustomRetention
* admin.conversations.setTeams
* admin.conversations.unarchive
* admin.conversations.unlinkObjects
* admin.emoji.add
* admin.emoji.addAlias
* admin.emoji.list
* admin.emoji.remove
* admin.emoji.rename
* admin.functions.list
* admin.functions.permissions.lookup
* admin.functions.permissions.set
* admin.inviteRequests.approve
* admin.inviteRequests.approved.list
* admin.inviteRequests.denied.list
* admin.inviteRequests.deny
* admin.inviteRequests.list
* admin.roles.addAssignments
* admin.roles.listAssignments
* admin.roles.removeAssignments
* admin.teams.admins.list
* admin.teams.create
* admin.teams.list
* admin.teams.owners.list
* admin.teams.settings.info
* admin.teams.settings.setDefaultChannels
* admin.teams.settings.setDescription
* admin.teams.settings.setDiscoverability
* admin.teams.settings.setIcon
* admin.teams.settings.setName
* admin.usergroups.addChannels
* admin.usergroups.addTeams
* admin.usergroups.listChannels
* admin.usergroups.removeChannels
* admin.usergroups.removeTeams
* admin.users.assign
* admin.users.getExpiration
* admin.users.invite
* admin.users.list
* admin.users.remove
* admin.users.session.clearSettings
* admin.users.session.getSettings
* admin.users.session.invalidate
* admin.users.session.list
* admin.users.session.reset
* admin.users.session.resetBulk
* admin.users.session.setSettings
* admin.users.setAdmin
* admin.users.setExpiration
* admin.users.setOwner
* admin.users.setRegular
* admin.users.unsupportedVersions.export
* admin.workflows.collaborators.add
* admin.workflows.collaborators.remove
* admin.workflows.permissions.lookup
* admin.workflows.search
* admin.workflows.triggers.types.permissions.lookup
* admin.workflows.triggers.types.permissions.set
* admin.workflows.unpublish
* agents
* api
* apps
* assistant
* auth
* blocks
* bookmarks
* bots
* calls
* canvases
* chat
* conversations
* dialog
* dnd
* emoji
* entity
* files
* functions
* lists
* migration
* oauth
* openid
* pins
* reactions
* reminders
* rtm
* search
* stars
* team
* tooling
* usergroups
* users
* views
* workflows
* Objects
* Scopes
* Types
* Slack Connect API
* Views
*
* Audit Logs API
* Legal Holds API
* SCIM API
*
* Slack Status API
*
* Methods
* admin
* admin.apps.permissions.set Copy as markdown
On this page
admin.apps.permissions.set method
Docs Call generator
The features within are only available to Slack workspaces on an Enterprise plan.
Don't have a paid plan? Join the Developer Program and provision a fully-featured sandbox for free.
Facts
Description Set the permission type for who can access an app
Method Access
* HTTP
* Slack CLI
* JavaScript
* Python
* Java POST https://slack.com/api/admin.apps.permissions.set
slack api admin.apps.permissions.set
app.client.admin.apps.permissions.set
app.client.admin_apps_permissions_set
app.client().adminAppsPermissionsSet
Scopes User token: admin.apps:write
Content types application/x-www-form-urlencoded
application/json
Rate Limits Tier 2: 20+ per minute
Arguments
Required arguments
token string Required
Authentication token bearing required scopes. Tokens should be passed as an HTTP Authorization header or alternatively, as a POST parameter.
Example: xxxx-xxxxxxxxx-xxxx
app_id string Required
Encoded ID of the app
Example: A0000000001
permission_type string Required
The type of permission that defines who can access the app
Acceptable values: everyone named_entities no_one
Optional arguments
user_ids array Optional
List of user IDs to allow for named_entities visibility
Example: ['U00000001', 'U00000002', 'U00000003']
usergroup_ids array Optional
List of encoded usergroup IDs
Example: S00000001,S00000002
channel_restriction_mode string Optional
The mode that defines where the app can be used in channels
Acceptable values: all_channels specific_channels all_channels_except
channel_ids array Optional
List of encoded channel IDs for channel restrictions. Semantics depend on channel_restriction_mode: allowlist for specific_channels, exclusion list for all_channels_except
Example: C00000001,C00000002
Usage info
This method sets an app's permission_type value, which defines who in the org can access the app. When the permission_type field is set to named_entities , pass either or both user_ids and usergroup_ids to define the specific entities that are granted access. Where permission_type controls which users can access the app, channel_restriction_mode controls which channels it can be used in: channel_restriction_mode value Description all_channels The app can be used in any channel. specific_channels The app can only be used in the channels listed in channel_ids (an allowlist). all_channels_except The app can be used in every channel except those listed in channel_ids (an exclusion list).
channel_ids is required when channel_restriction_mode is specific_channels or all_channels_except , but is not required for all_channels . Channel restrictions can't be configured while permission_type is no_one , since the app can't be used in any channel. To adjust the channel list later without resending it in full, use the admin.apps.permissions.add and admin.apps.permissions.remove methods. To grant access for individual entities without changing the permission type, use the admin.apps.permissions.add method. To revoke access, use the admin.apps.permissions.remove method. To view the current permission type and its entities, use the admin.apps.permissions.list method.
Response
When channel restrictions are configured, the response also includes channel_restriction_mode and, for specific_channels or all_channels_except , the channel_ids it applies to. When permission_type is no_one , the response returns channel_restriction_mode as no_one , since the app can't be used in any channel.
{
"ok" : true ,
"permission_type" : "everyone" ,
"channel_restriction_mode" : "specific_channels" ,
"channel_ids" : [
"C00000001" ,
"C00000002"
]
}
Errors
This table lists the expected errors that this method could return. However, other errors can be returned in the case where the service is down or other unexpected factors affect processing. Callers should always check the value of the ok parameter in the response. Error
Description
access_denied
This actor does not have access to the permissions on this resource.
access_denied
Access to a resource specified in the request is denied.
accesslimited
Access to this method is limited on the current network
account_inactive
Authentication token is for a deleted user or workspace when using a bot token.
app_not_found
This app does not exist.
channel_ids_required
channel_ids is required when channel_restriction_mode is specific_channels or all_channels_except.
channel_not_found
One or more channel IDs are not valid.
channel_restriction_requires_app_access
Channel access cannot be configured while the app is set to no_one, since the app can't be used in any channel.
channel_restrictions_not_available
Channel restrictions are not available for this workspace.
deprecated_endpoint
The endpoint has been deprecated.
ekm_access_denied
Administrators have suspended the ability to post a message.
enterprise_is_restricted
The method cannot be called from an Enterprise.
fatal_error
The server could not complete your operation(s) without encountering a catastrophic error. It's possible some aspect of the operation succeeded before the error was raised.
internal_error
The server could not complete your operation(s) without encountering an error, likely due to a transient issue on our end. It's possible some aspect of the operation succeeded before the error was raised.
invalid_arg_name
The method was passed an argument whose name falls outside the bounds of accepted or expected values. This includes very long names and names with non-alphanumeric characters other than _ . If you get this error, it is typically an indication that you have made a very malformed API call.
invalid_arguments
The method was called with invalid arguments.
invalid_array_arg
The method was passed an array as an argument. Please only input valid strings.
invalid_auth
Invalid authorization token
invalid_auth
Some aspect of authentication cannot be validated. Either the provided token is invalid or the request originates from an IP address disallowed from making the request.
invalid_channel_restriction_mode
The channel_restriction_mode value is not valid.
invalid_charset
The method was called via a POST request, but the charset specified in the Content-Type header was invalid. Valid charset names are: utf-8 iso-8859-1 .
invalid_form_data
The method was called via a POST request with Content-Type application/x-www-form-urlencoded or multipart/form-data , but the form data was either missing or syntactically invalid.
invalid_permission_type
This app requires permission_type to be set as named_entities before adding users.
invalid_post_type
The method was called via a POST request, but the specified Content-Type was invalid. Valid types are: application/json application/x-www-form-urlencoded multipart/form-data text/plain .
method_deprecated
The method has been deprecated.
missing_post_type
The method was called via a POST request and included a data payload, but the request did not include a Content-Type header.
missing_scope
The token used is not granted the specific scope permissions required to complete this request.
named_entities_cannot_be_empty
Must pass at least one valid named entity.
no_permission
The workspace token used in this request does not have the permissions necessary to complete the request. Make sure your app is a member of the conversation it's attempting to post a message to.
no_valid_named_entities
None of the provided named entities were valid
not_allowed_token_type
The token type used in this request is not allowed.
not_an_enterprise
This feature is only available on Enterprise Grid plans.
not_authed
No authentication token provided.
org_login_required
The workspace is undergoing an enterprise migration and will not be available until migration is complete.
ratelimited
The request has been ratelimited. Refer to the Retry-After header for when to retry the request.
request_timeout
The method was called via a POST request, but the POST data was either missing or truncated.
restricted_action
User does not have permission to perform this action.
service_unavailable
The service is temporarily unavailable
team_access_not_granted
The token used is not granted the specific workspace access required to complete this request.
team_added_to_org
The workspace associated with your request is currently undergoing migration to an Enterprise Organization. Web API and other platform operations will be intermittently unavailable until the transition is complete.
token_expired
Authentication token has expired
token_revoked
Authentication token is for a deleted user or workspace or the app has been removed when using a user token.
too_many_named_entities
Too many named_entities passed into the app permissions setting.
two_factor_setup_required
Two factor setup is required.
user_not_found
This actor does not have access to at least one valid named entity.
usergroup_not_found
The usergroup is not valid.
Previous
admin.apps.permissions.remove
Next
admin.apps.requests.cancel
Copy as markdown
* Facts
* Arguments
* Usage info
* Response
* Errors
.
*
Tools
* Slack CLI
* Bolt frameworks
* Slack SDKs
* Block Kit Builder
* Developer program
* Code samples & tutorials
* LLM? Read llms.txt
* All tools
Learn
* Learning paths
* Workshops
* Slack certifications
* Trailhead
* Resource library
* All learning resources
Community
* Slack community
* Slack events
Resources
* Docs
* Blog
* Slack marketplace
* Developer newsletter
Manage Apps
* Your apps
* Status
* Privacy
* Terms
* Cookie Preferences
* Support
* Changelog
* Your Privacy Choices
© 2026 Slack Technologies, LLC, a Salesforce company. All rights reserved. Various trademarks held by their respective owners.
*
*
*
Links found on this page
- Skip to main content [direct]
- Guides [direct]
- Reference [direct]
- Samples [direct]
- Tools [direct]
- Changelog [direct]
- Dev Program [direct]
- MANAGE APPS [direct]
- Reference [direct]
- App manifest [direct]
- Block Kit [direct]
- Events [direct]
- Interaction payloads [direct]
- Methods [direct]
- admin [direct]
- admin.analytics.messages.activity [direct]
- admin.analytics.messages.metadata [direct]
- admin.apps.activities.list [direct]
- admin.apps.approve [direct]
- admin.apps.approved.list [direct]
- admin.apps.clearResolution [direct]
- admin.apps.config.lookup [direct]
- admin.apps.config.set [direct]
- admin.apps.mcp.servers.list [direct]
- admin.apps.mcp.servers.permissions.list [direct]
- admin.apps.mcp.servers.permissions.set [direct]
- admin.apps.permissions.add [direct]
- admin.apps.permissions.list [direct]
- admin.apps.permissions.remove [direct]
- admin.apps.permissions.set [direct]
- admin.apps.requests.cancel [direct]
- admin.apps.requests.list [direct]
- admin.apps.restrict [direct]
- admin.apps.restricted.list [direct]
- admin.apps.uninstall [direct]
- admin.audit.anomaly.allow.getItem [direct]
- admin.audit.anomaly.allow.updateItem [direct]
- admin.auth.policy.assignEntities [direct]
- admin.auth.policy.getEntities [direct]
- admin.auth.policy.removeEntities [direct]
- admin.barriers.create [direct]
- admin.barriers.delete [direct]
- admin.barriers.list [direct]
- admin.barriers.update [direct]
- admin.conversations.archive [direct]
- admin.conversations.bulkArchive [direct]
- admin.conversations.bulkDelete [direct]
- admin.conversations.bulkMove [direct]
- admin.conversations.bulkSetExcludeFromSlackAi [direct]
- admin.conversations.bulkSetProperties [direct]
- admin.conversations.convertToPrivate [direct]
- admin.conversations.convertToPublic [direct]
- admin.conversations.create [direct]
- admin.conversations.createForObjects [direct]
- admin.conversations.delete [direct]
- admin.conversations.disconnectShared [direct]
- admin.conversations.ekm.listOriginalConnectedChannelInfo [direct]
- admin.conversations.getConversationPrefs [direct]
- admin.conversations.getCustomRetention [direct]
- admin.conversations.getTeams [direct]
- admin.conversations.invite [direct]
- admin.conversations.linkObjects [direct]
- admin.conversations.lookup [direct]
- admin.conversations.removeCustomRetention [direct]
- admin.conversations.rename [direct]
- admin.conversations.restrictAccess.addGroup [direct]
- admin.conversations.restrictAccess.listGroups [direct]
- admin.conversations.restrictAccess.removeGroup [direct]
- admin.conversations.search [direct]
- admin.conversations.setConversationPrefs [direct]
- admin.conversations.setCustomRetention [direct]
- admin.conversations.setTeams [direct]
- admin.conversations.unarchive [direct]
- admin.conversations.unlinkObjects [direct]
- admin.emoji.add [direct]
- admin.emoji.addAlias [direct]
- admin.emoji.list [direct]
- admin.emoji.remove [direct]
- admin.emoji.rename [direct]
- admin.functions.list [direct]
|
|